Impact
A stored XSS exists in WatchGuard Dimension’s task scheduling feature. An attacker with low‑privilege admin access can inject HTML or JavaScript into the scheduling fields, and those scripts are executed when any user views the scheduled task. The attacker can therefore hijack user sessions, steal cookies, or perform actions with the victim’s privileges.
Affected Systems
WatchGuard Dimension installations prior to version 2.3.1. The vendor has released a fix in Dimension 2.3.1 to eliminate this flaw.
Risk and Exploitability
The CVSS base score of 5.1 signifies moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attacker must be a low‑privileged authenticated administrator to insert the payload, limiting the initial attack vector, but once the malicious task is viewed, the compromised script runs automatically for any user who opens the task, potentially impacting many users.
OpenCVE Enrichment